Skip to content
mcp/skillhub

PostgreSQL (hardened, read-only) MCP Server

by eszetaelio.github.Eszetael/postgres-mcp-hardenedv0.1.10

Read-only PostgreSQL access: AST-validated queries in read-only transactions, schema inspection, column redaction, EXPLAIN cost guard and audit log.

3Node.jsstdioremoteofficial registry

context tax

queued

security

queued

cold start

queued

freshness

Maintained35d ago

Install PostgreSQL (hardened, read-only) MCP server

Install in Claude Code

claude mcp add postgres-mcp-hardened -e DATABASE_URL='<database-url>' -- npx -y postgres-mcp-hardened

Configuration

VariableRequiredSecretDescription
DATABASE_URLyesyesConnection string for the role the server connects as. Use a role that cannot write — the server refuses writes twice, but a read-only role is the layer that does not depend on us being correct. `--print-setup-sql` prints the SQL that creates one.
MCP_STATEMENT_TIMEOUT——Server-side statement timeout, e.g. `5s`. A question that would pin the database is cancelled by PostgreSQL, not by hope.
MCP_ALLOW_TABLES——Comma-separated allowlist. A table off the list is refused by name, and hiding it inside a CTE, a view or a join does not help.
MCP_AUDIT_LOG——Path to the tamper-evident audit log. Entries are chained by hash and survive a restart; `--verify-audit` checks the chain against an off-host anchor.
MCP_ADDR——Address to bind, default 127.0.0.1:8080.

Freshness

Maintained — last maintenance signal 35d ago. The newest of the signals below sets the band.

  1. Last commit (default branch)

    2026-09-04 · 35d ago · GitHub

  2. Latest release

    2026-09-04 · 35d ago · GitHub · v0.1.10

  3. Package published

    no data · npm/PyPI

  4. Registry entry updated

    2026-09-04 · 35d ago · official registry · v0.1.10

FAQ

›How do I install the PostgreSQL (hardened, read-only) MCP server in Claude Code?

Run: claude mcp add postgres-mcp-hardened -e DATABASE_URL='<database-url>' -- npx -y postgres-mcp-hardened. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.

›Does PostgreSQL (hardened, read-only) require an API key?

Yes. It expects DATABASE_URL, of which 1 is a secret.

›Can I use PostgreSQL (hardened, read-only) as a remote (hosted) MCP server?

Yes — it offers both a hosted endpoint and a local stdio package.

›Is PostgreSQL (hardened, read-only) in the official MCP registry?

Yes, as io.github.Eszetael/postgres-mcp-hardened.

Alternatives to PostgreSQL (hardened, read-only)

Other database MCP servers.

View all